Is Google Analytics Legal in the Netherlands? Cookie Consent, 10,000 Sites Scanned, and the Exemption

The Dutch flag blended with a ghosted Google Analytics 4 interface, with the AP's Takeaway.com reprimand and the analytics exemption highlighted, next to the Clickport logo.
Legal status re-verified against primary sources in July 2026. Every ruling and figure below links to the original decision or report.

715,000 Dutch websites use Google Analytics. The Autoriteit Persoonsgegevens monitors 10,000 of them a year for cookie compliance, and GA plainly fails the Dutch analytics exemption's criteria on third-party data use alone. Yet the AP's only enforcement action against Google Analytics was a reprimand against Takeaway.com that was never made public. In plain English: the strictest cookie regime in Europe has produced exactly one private slap on the wrist. For a country with 99% internet penetration, the gap between what the rules say and what happens is worth understanding. Here's the full picture as I read it in July 2026.

Key Takeaways
  • Dutch cookie consent has required a clear affirmative action since 2012, with no implied-consent loophole, and the AP treats cookie walls as invalid consent. The 2015 amendment to the Telecommunicatiewet added a statutory analytics exemption most site owners have never heard of.
  • The AP monitors 10,000 Dutch websites annually for cookie compliance with dedicated government funding of EUR 500,000 per year. Kruidvat was fined EUR 600,000 for tracking cookies on health product pages. Coolblue paid EUR 40,000 for pre-ticked consent boxes.
  • The Netherlands has a statutory analytics exemption: analytics cookies can run without consent if they are first-party only, IP addresses are anonymized, no cross-site tracking occurs, and data is not shared with third parties. Google Analytics fails these criteria, and the AP has quietly withdrawn its old guide for privacy-friendly GA setup.
  • The AP's only Google Analytics enforcement was a formal reprimand against Takeaway.com for Universal Analytics data transfers to the US. It was never made public, and the AP says those findings do not carry over one-to-one to GA4. 715,000 Dutch websites still use Google Analytics.
  • In comparable EU markets, fewer than 1 in 4 visitors accepts cookies. Combined with roughly 20% ad blocker usage and Safari's tracking protection, cookie-based analytics miss a large share of Dutch traffic. Cookieless analytics that meet the audience-measurement exemption criteria require no consent under the Telecommunicatiewet.

The Dutch privacy paradox

Amsterdam is one of Europe's largest internet hubs. AMS-IX, the Amsterdam Internet Exchange, handles over 14 Tbps at peak. That means 14 trillion bits crossing Amsterdam every second. The Netherlands has 99% internet penetration, tied with Denmark, Norway, and Switzerland for the highest in Europe. In plain English: effectively everyone in the country is online. It's home to Startpage (the world's most private search engine) and Bits of Freedom (one of Europe's oldest digital rights organizations).

It also has one of Europe's strictest cookie laws, one of its most active privacy regulators, and a deeply rooted cultural commitment to data protection that goes back decades.

The Netherlands enacted data protection legislation in 1989, nearly a decade before most European peers. Put another way: the Dutch had a privacy law before the web had a browser. In 1995, the Dutch Data Protection Authority and the Netherlands Organisation for Applied Scientific Research (TNO) co-authored the foundational paper on Privacy Enhancing Technologies with Ontario's Information and Privacy Commissioner. That work became the basis for Privacy by Design, later codified as GDPR Article 25. The roots of this privacy culture run deep: the wartime abuse of the Dutch population registry left a lasting mark on how the country thinks about state and corporate data collection.

In 2018, five university students organized a national referendum against the Intelligence and Security Services Act (known as "de Sleepwet," the Dragnet Law), which granted Dutch intelligence services bulk surveillance powers. 49.44% voted against. That means 1 voter in 2 said no, and the law passed anyway, with modifications.

Dutch privacy milestones
1989
Personal Data Protection Act. One of Europe's earliest data protection laws.
1995
Dutch DPA and TNO co-author Privacy Enhancing Technologies paper. The origin of Privacy by Design.
2015
Telecommunicatiewet amended. The statutory analytics exemption is added to Article 11.7a.
2018
Sleepwet referendum. 49.44% of Dutch citizens vote against bulk surveillance law. Government passes it anyway.
2024
First cookie fines. Kruidvat (EUR 600,000) and Coolblue (EUR 40,000) fined for tracking cookies without valid consent.
2026
AP monitors 10,000 websites annually. Dedicated cookie enforcement budget. Warns 500 organizations per year.

The country that routes a huge share of Europe's internet traffic also has some of the strictest rules about what you can track on it.

The Autoriteit Persoonsgegevens: 300+ staff and a leadership transition

The Autoriteit Persoonsgegevens (AP) is the Dutch Data Protection Authority. It has over 300 staff, a 2026 budget of EUR 53.5 million, and offices in The Hague. Chair Aleid Wolfsen has led the AP since 2016. His term ends in August 2026, and his successor is already named: Geert Potjewijd, a data protection lawyer from De Brauw, takes the chair on 1 August 2026.

Wolfsen's AP doesn't hesitate. It fined Uber EUR 290 million in July 2024 for transferring European drivers' sensitive data to the US without adequate safeguards, one of the largest single GDPR fines ever issued. Put another way: this regulator writes nine-figure fines when it decides to move. It fined Clearview AI EUR 30.5 million for building an illegal facial recognition database, and investigated whether Clearview's directors could be held personally liable. In other words: fines first, and maybe your directors next. And in May 2026 it fined the taxi app Yango EUR 100 million for transferring customer data to Russia, its second-largest fine ever. It processed nearly 40,000 data breach notifications and 8,500 citizen complaints in 2024, with complaints jumping to 13,500 in 2025. That means roughly 50 complaints landing every working day.

The AP by the numbers (2026)
300+
Staff (FTE)
€53.5M
Annual budget
10,000
Websites scanned/year
€290M
Largest single fine (Uber)
The AP says it needs EUR 100 million/year to fulfill its mandate. It currently has barely half. Sources: AP Facts & Figures, iBestuur (Prinsjesdag 2025)

Cookie enforcement has become a specific focus. The AP built an automated scanning system that structurally monitors 10,000 Dutch websites for cookie compliance. The Dutch government allocated EUR 500,000 per year for three years specifically for cookie enforcement, followed by a permanent EUR 350,000 annual top-up from 2027. That means cookie scanning is a budget line now, not a side project. In April 2025, the AP warned 50 organizations (online retailers, media companies, insurers) about misleading cookie banners. By late 2025, three-quarters of the 200+ warned websites had adjusted their banners. Which means warnings alone fixed 3 sites in 4. Those that refused face formal investigation.

An illustration of a cookie compliance scan result for a redacted Dutch sample site, marked NOT COMPLIANT, with 23 cookies detected including five Google Analytics cookies set before any consent action, 11 third-party trackers, and 3 Telecommunicatiewet violations flagged.
Recreated for illustration: the kind of result an automated compliance scan produces for a typical Dutch site. Cookies before consent, no top-level reject, and third-party data sharing that disqualifies the analytics exemption.

The AP's 2026-2028 strategic priorities explicitly reclassify online tracking as a form of "mass surveillance." The stated position: people should be able to move freely online without being constantly tracked or observed. This is a regulator that treats your cookie banner the same way it treats a CCTV camera. I don't know another DPA that states it that bluntly.

The August 2026 handover to Potjewijd is the most significant variable. He could maintain the current enforcement posture, or adjust it. Either way, the infrastructure is in place: automated scanning, dedicated budget, and a 500-organization-per-year warning pipeline.

Chrome DevTools Network panel on a Dutch e-commerce page during initial page load. The site logo and domain reference in the page hero are blurred for privacy. Six requests are shown in chronological order, with rows 3, 4, and 5 highlighted: gtm.js, gtag/js, and g/collect, the three Google tracking endpoints. A red annotation banner overlays the waterfall reading 'GA cookies set at 720 ms - Cookie banner only renders at 1,420 ms' with a red arrow pointing to the g/collect row. A cookie-preview tooltip in the corner shows _ga, _ga_*, and _gid cookies already set on the visitor's device.
What an AP-style scan of a typical Dutch e-commerce page finds: the GA cookies set at 720 ms, the cookie banner only renders at 1,420 ms. The cookies the Telecommunicatiewet regulates have already been written before the visitor sees any consent option.

Cookie consent in the Netherlands is governed by Article 11.7a of the Telecommunicatiewet (Telecommunications Act), the Dutch implementation of the EU ePrivacy Directive. This is the actual cookie law. Most Dutch website owners have heard of the AVG (the Dutch name for the GDPR). Far fewer know about the Telecommunicatiewet. But Article 11.7a is what determines whether you can set a cookie in the first place.

Explicit consent is required for all non-essential cookies. That requirement dates from the 2012 Dutch implementation of the EU ePrivacy Directive. No implied consent from browser settings. No consent inferred from continued browsing. The user must take a clear affirmative action before any non-essential cookie fires. In other words: nothing fires until your visitor says yes. The 2015 amendment went the other direction: it added the statutory analytics exemption covered below.

Cookie walls are banned. The AP has consistently interpreted the GDPR's "freely given" consent standard as prohibiting cookie walls, and Article 11.7a(5) bans them outright for public-sector websites. If you block access to your website unless visitors accept tracking cookies, the consent isn't freely given and therefore invalid. The Netherlands was among the first EU countries to take this position, years before GDPR Article 7(4) and Recital 42 reinforced the same principle at the EU level.

Two exemptions exist. A cookie is exempt if it's: (a) strictly necessary for transmitting a communication over a network, or (b) strictly necessary for providing a service the user explicitly requested. Session management, shopping carts, authentication, CSRF tokens, language preferences.

How Dutch cookie law works: two layers
Layer 1: Telecommunicatiewet (device access)
"Can I store or read data on this visitor's device?"
Applies even if no personal data is involved
Only legal basis: consent (or strictly necessary exemption)
Legitimate interest does NOT apply at this layer
↓ Only after Telecommunicatiewet is satisfied ↓
Layer 2: AVG/GDPR (data processing)
"How can I process the personal data collected?"
Only applies if personal data is processed
Six lawful bases available (consent, legitimate interest, etc.)
If you already have Tw consent, use consent as your GDPR basis too
Cookieless analytics still fall under Article 5(3) when they access device properties, but qualify for the audience-measurement exemption under Article 11.7a. No consent required.

Consent must meet the GDPR standard. Since 2015, Dutch cookie consent must be freely given, specific, informed, and an unambiguous indication by clear affirmative action. Reject must be as easy as Accept. Pre-ticked boxes are invalid. No dark patterns, no deceptive colour contrast, no hiding the reject option behind multiple clicks. Our cookie banner decision flowchart walks through these design checks.

One structural quirk: the cookie provision itself (Article 11.7a) is formally supervised by the ACM (Authority for Consumers & Markets), while the AP enforces the GDPR side whenever cookies process personal data. That GDPR route is how Kruidvat and Coolblue were fined. In March 2025 the two regulators jointly proposed moving cookie supervision entirely to the AP; as of July 2026 that hasn't been enacted.

The Dutch analytics exemption

This is where the Netherlands diverges from most EU countries. The exemption is written into the law itself: Article 11.7a(3)(b) exempts cookies used to measure the quality or effectiveness of a delivered service, provided they have no or only minor impact on the visitor's privacy. That clause was added in 2015.

What counts as "no or minor privacy impact"? Regulators and practice have fleshed the statutory wording out into strict conditions. An analytics cookie qualifies only if it meets all of the following:

  1. First-party only. The cookie is set by the website itself, not by a third-party domain.
  2. IP addresses are anonymized or masked.
  3. No cross-site tracking. The cookie doesn't track visitors across different websites.
  4. Data isn't shared with third parties for their own purposes.
  5. Minimal privacy impact. The data is used solely to measure website performance and quality.

If your tool meets all five, you can run analytics without asking anyone to click a banner. If it misses even one, you're back to consent.

Two paths to analytics compliance in the Netherlands
Cookie-based analytics (GA4)
Must pass 5 AP exemption conditions
GA4 fails: data shared with Google
Requires cookie consent banner
Most visitors reject or ignore the banner
Result: you only see the minority who click Accept
Cookieless analytics (Clickport)
No cookies = exemption not needed
No consent banner required
No data sent to third parties
Every visitor counted from day one
Result: nearly all your Dutch traffic, fully compliant
GA4 fails the exemption criteria because data is shared with Google for its own purposes. The AP has quietly removed its old privacy-friendly GA setup guide; its current guidance names other tools as consent-free examples instead. Source: AP cookie guidance

The exemption is generous by European standards. France's CNIL initially required consent even for audience measurement cookies before softening its position in 2020. Germany only clarified its approach after the TTDSG (since renamed TDDDG) took effect in December 2021, and still offers no analytics exemption at all. Belgium explicitly rejected an exemption request from seven industry associations. The Dutch exemption has been in place since 2015. Put another way: the Netherlands solved in 2015 what Brussels is still debating in 2026.

There's a telling detail in how the AP's position on Google Analytics has evolved. For years the AP published a manual for setting up GA in a privacy-friendly way. That manual is gone: the pages quietly disappeared around 2023 and now return 404s. The AP's current business guidance doesn't mention Google Analytics at all. Instead it names Matomo, Apache Superset, Plausible Analytics, and OpenPanel as examples of tools that, correctly configured, can run without consent. In other words: the regulator stopped explaining how to make GA compliant and started listing alternatives.

The exemption applies to cookie-based tools that genuinely meet all five conditions. Clickport takes a different path: it uses no cookies and no persistent identifiers, but any JavaScript-based analytics tool, including Clickport, still falls under Article 5(3) when it reads device properties like screen width or timezone. The difference is that Clickport's architecture meets the audience-measurement exemption criteria by design: first-party only, no cross-site tracking, no persistent identifiers, aggregate output. No consent required: not because Article 5(3) doesn't apply, but because the exemption covers it.

Google Analytics in the Netherlands: reprimand, not a ban

Unlike Austria (December 2021), France (February 2022), and Italy (June 2022), the AP never banned Google Analytics.

The AP was part of the EDPB Task Force 101, set up in September 2020 to coordinate a consistent response to the 101 identical complaints noyb filed across EEA data protection authorities. While Austria, France, Italy, Denmark, and Finland issued formal decisions declaring GA unlawful, the Netherlands took a different path.

On 20 August 2024, the AP issued a formal reprimand against Takeaway.com Group B.V. for violating GDPR Article 44 by transferring personal data to the US via Google Analytics between August 2020 and September 2023 without valid legal mechanisms. No fine. That means 3 years of violations priced at zero euros. The reprimand was not made public under the AP's standard disclosure policy. It surfaced through the complainant, a Freedom of Information decision, and parliamentary answers rather than any AP announcement. In other words: the Netherlands' entire GA enforcement history fits in one unpublished letter.

In a November 2025 advisory used to answer parliamentary questions (published December 2025), the AP confirmed that its investigation resulted only in this reprimand, that no separate published decision exists, and that a total ban on Google Analytics isn't on the table. The AP's famous February 2022 warning that "the use of Google Analytics may soon not be allowed" quietly ended in that single unpublished letter.

Google Analytics enforcement across Europe
Austria (DSB)
Formal decision: GA declared unlawful (Dec 2021)
Banned
France (CNIL)
Formal orders to stop GA use (Feb 2022)
Banned
Italy (Garante)
Formal decision: GA declared unlawful (Jun 2022)
Banned
Netherlands (AP)
Private reprimand against Takeaway.com. No fine. Not published. GA4 not investigated.
Reprimanded
The EU-US Data Privacy Framework (July 2023) restored legal cover for the transfers. It survived its first court test in September 2025, but a CJEU appeal is pending and FISA 702 lapsed in June 2026. For now, the remaining question is cookie consent, not data transfers.

Three critical details:

The reprimand concerned Universal Analytics only. The AP's account covers GA version 3 and, in the AP's own words, doesn't carry over one-to-one to today's GA4. The violation period ended in September 2023, when Google implemented the EU-US Data Privacy Framework.

The remaining compliance obligation is cookie consent. The data transfer issue is resolved by the DPF for now. But GA4 still requires a cookie (_ga) to function. Under the Telecommunicatiewet, that cookie needs explicit consent before it fires. The Dutch analytics exemption doesn't reach GA4 because Google uses analytics data for its own purposes.

715,000 Dutch websites still use Google Analytics. According to BuiltWith's running count (as of mid-2026), GA remains the dominant analytics platform in the Netherlands. That means the reprimand changed almost nothing on the ground. The Dutch government is an exception: it announced in December 2025 that it would stop using Google Analytics on werkenvoornederland.nl (the government job vacancy site), after it emerged GA was running on pages where applicants applied to intelligence services. Which means even the government's own house wasn't in order.

Notable enforcement actions

A Dutch-language cookie consent banner overlaid on a sample e-commerce site. The site logo and brand name in the page background are blurred. Four cookie categories are listed (Noodzakelijke, Functionele, Statistische incl. Google Analytics, Marketing incl. Google Ads and Facebook Pixel), with all four checkboxes pre-ticked including the non-essential ones. A large blue 'Alles accepteren' button dominates the action area, with a much smaller 'Cookie-instellingen aanpassen' link demoted underneath. Privacybeleid and Cookiebeleid links sit in the banner footer.
The cookie banner pattern that cost Coolblue EUR 40,000 and Kruidvat EUR 600,000. Statistics and Marketing categories pre-ticked, "Alles accepteren" visually dominant, "Cookie-instellingen aanpassen" demoted to a small grey link. Under the Telecommunicatiewet this is not freely given consent.

The AP has enforced across a broad range of industries. The cookie-specific cases set the clearest precedent for website owners.

A.S. Watson / Kruidvat: EUR 600,000 (July 2024). Tracking cookies were placed on Kruidvat.nl without valid consent. Cookie consent checkboxes were pre-ticked. Visitors who wanted to refuse had to navigate multiple steps. The AP singled out that the tracked pages included personal health product categories, making the privacy impact more severe. The investigation started in late 2019. The violation was resolved in October 2020, but the fine still came. In plain English: fixing it four years before the ruling didn't erase the bill.

Coolblue: EUR 40,000 (fine decision January 2024, reduced after objection in December 2024). Coolblue automatically assumed visitor consent with pre-checked cookie boxes. Coolblue's objection partly succeeded, and EUR 40,000 is the final reduced amount. The fine was small. The precedent wasn't.

Uber: EUR 290 million (July 2024). European drivers' personal data, including location data, taxi licenses, photos, payment information, identity documents, and criminal and medical records, was transferred to the US without adequate safeguards for over two years. This was Uber's third AP fine (after EUR 600,000 in 2018 and EUR 10 million in December 2023). That means 3 fines in 6 years for one company.

Clearview AI: EUR 30.5 million (September 2024). Illegal collection of billions of facial images for a facial recognition database, including Dutch citizens. Plus orders backed by penalty payments of up to EUR 5.1 million for continued non-compliance.

Top AP enforcement actions
Uber
US data transfers without safeguards (27 months)
€290,000,000
Yango
Customer data transfers to Russia (May 2026)
€100,000,000
Clearview AI
Illegal facial recognition database
€30,500,000
Uber (second)
Non-transparent privacy policy, data access rights
€10,000,000
Dutch Tax Administration (FSV)
Illegal fraud blacklist, 270,000+ people
€3,700,000
Dutch Tax Administration
Nationality discrimination in childcare benefits
€2,750,000
A.S. Watson (Kruidvat)
Tracking cookies on health product pages without consent
€600,000

Dutch courts have reinforced the cookie rules too. In October 2023, in a case brought by an individual Dutch internet user, the Amsterdam District Court ruled that ad tech company Criteo violated the GDPR by placing tracking cookies without consent on 39 of 40 websites tested. Criteo was held jointly responsible with its publisher partners for ensuring valid consent. In plain English: the cookie duty follows the cookie, not just the website. In June 2024, the Amsterdam court prohibited LinkedIn, Microsoft, and Xandr from placing tracking cookies without user consent. And in November 2025, the Rotterdam District Court refused to lift the tracking-cookie ban on Criteo and declared its conduct unlawful.

The principle: companies that place cookies through third-party websites are joint controllers. They can't outsource consent responsibility to publishers.

What's coming in 2026 and beyond

Three developments will shape Dutch cookie law over the next two years. Here's what I'd watch.

A new chair (August 2026). Geert Potjewijd, a De Brauw lawyer who co-headed the firm's data protection practice, becomes AP chair on 1 August 2026. He inherits a regulator with automated scanning infrastructure, dedicated cookie enforcement funding, and a three-year strategic plan that treats online tracking as surveillance. The enforcement machinery runs regardless of who sits in the chair. But tone and priorities can shift.

The Digital Omnibus. The EU-wide analytics exemption it proposes is similar to the Dutch exemption that already exists. But the Netherlands has raised serious concerns about the proposal, supporting simplification but rejecting changes that weaken protections. Earliest practical impact: 2028.

Key insight
The ePrivacy Regulation was officially withdrawn by the Commission in July 2025 after eight years of failed negotiations. The Digital Omnibus is now the only legislative vehicle for EU cookie reform. Until it passes, the Telecommunicatiewet remains in force.

AP 2026 priorities: online tracking as mass surveillance. The AP's 2026-2028 strategic focus has three pillars: mass surveillance, artificial intelligence, and digital resilience. Online tracking and cookie profiling are explicitly categorized under "mass surveillance" alongside camera surveillance and law enforcement practices. The AP plans to warn 500 organizations per year about cookie violations and continue structural monitoring of 10,000 websites. That means 10 warning letters every working week. This isn't slowing down.

Check your own site
See what your site loads before consent.
Paste your URL into the free GDPR checker. It reads your page source, identifies every tracking script, and checks whether each one is gated behind consent, which is where Autoriteit Persoonsgegevens guidance starts. No signup, about thirty seconds.
Scan your site for trackers →

What this means for your website

Google Tag Manager Preview and Debug mode showing three tags fired on the 'Container Loaded' event on a redacted Dutch sample site. The Connected status bar and the Selected Event Details panel have their domain references blurred for privacy. The tag cards show GA4 Configuration setting _ga and _ga_* first-party cookies, GA4 Event firing page_view at 312ms via google-analytics.com/g/collect, and Google Ads Conversion Linker setting _gcl_au. A yellow warning banner at the bottom reads: 'Notice: All 3 tags fired BEFORE consent_update event. Verify Consent Mode v2 configuration before deploying to EU sites.'
Google Tag Manager's debug view of a typical Dutch site setup. Three tags fire on Container Loaded, three first-party Google cookies are written, all before any consent_update event. The yellow warning at the bottom is Tag Manager's own flag that this configuration does not meet EU consent requirements.

If you run a website targeting Dutch visitors, here's the practical picture.

The rules are clear. Non-essential cookies require explicit consent. Cookie walls are banned. Reject must be as easy as Accept. Pre-ticked boxes are invalid. The AP scans 10,000 websites a year and has dedicated funding to enforce.

The analytics exemption is narrow. First-party, IP-anonymized, no cross-site tracking, no data sharing. Google Analytics doesn't qualify. A correctly configured first-party cookie tool might. Cookieless analytics that meet the exemption criteria (no persistent identifiers, no cross-site tracking, first-party only, aggregate output) require no consent under Article 11.7a.

Most Dutch visitors never grant analytics consent. In comparable European markets, fewer than 1 in 4 visitors accepts cookies, and the Dutch privacy culture gives no reason to expect friendlier numbers here. Combined with roughly 20% ad blocker usage, cookie-based analytics miss a significant share of your Dutch traffic. In plain English: consent-gated analytics starts blind to most of your visitors.

Cookie-based analytics data loss in the Netherlands
<25%
Typical cookie acceptance in comparable EU markets
~20%
Use ad blockers
~16%
Safari users (ITP blocks third-party cookies)
These groups overlap. But the pattern is consistent: cookie-based analytics tools see an incomplete picture of Dutch traffic. Sources: CookieYes, StatCounter, Statista
Is your Dutch website cookie-compliant?
Answer these questions about your analytics setup to check your compliance with Dutch cookie law.
1. Does your analytics tool set cookies on visitors' devices?
2. Do you collect explicit, affirmative consent before any non-essential cookies fire?
3. Is your "Reject" button as prominent as your "Accept" button (same size, same colour weight)?
4. Can visitors access your full website without accepting tracking cookies (no cookie wall)?
5. Does your analytics provider process data solely for your purposes (not for their own advertising or AI)?
6. Can visitors withdraw cookie consent as easily as they gave it?

Not sure where your site stands? Run it through our free GDPR compliance checker for a quick audit.

The simplest path to compliance in the Netherlands is to remove the thing that triggers the Telecommunicatiewet in the first place. Cookieless analytics mean no consent requirement, no cookie banner, no cookie wall concerns, and no risk of being one of the 500 organizations the AP warns this year. We ranked the leading cookieless options in our GA alternatives comparison, and our privacy-friendly analytics guide explains how cookieless tools work in detail.

Frequently asked questions

Google Analytics isn't banned in the Netherlands. The AP issued a private reprimand against Takeaway.com for Universal Analytics data transfers; its findings don't carry over one-to-one to GA4, and it has stated that a total ban isn't on the table. However, GA4 requires a cookie, and it fails the Dutch analytics exemption criteria because data is shared with Google for its own purposes. You need valid cookie consent before firing GA4 on a Dutch website.

The AP allows certain first-party analytics cookies without consent if they meet five conditions: first-party only, IP addresses anonymized, no cross-site tracking, data not shared with third parties, and used solely for aggregate website performance measurement. A first-party cookie tool configured correctly can qualify. Google Analytics doesn't, because data is shared with Google for its own purposes. In plain English: your analytics can skip the banner only if your vendor never touches the data for itself.

No. The AP consistently interprets the "freely given" consent standard as prohibiting cookie walls, and Article 11.7a(5) of the Telecommunicatiewet bans them outright for public-sector websites. Blocking access to your website unless visitors accept tracking cookies means consent isn't freely given and is therefore invalid. The Netherlands was among the first EU countries to take this position. The GDPR later reinforced it at the EU level through Article 7(4) and Recital 42.

The AP fined A.S. Watson (Kruidvat) EUR 600,000 in July 2024 for placing tracking cookies on health product pages without valid consent, and Coolblue EUR 40,000 for pre-ticked cookie consent boxes (a January 2024 fine, reduced to that amount after Coolblue's objection partly succeeded in December 2024). The AP has also warned over 200 websites about misleading cookie banners and plans to warn 500 organizations per year. That means your odds of getting a letter are real if you run pre-ticked boxes.

If your analytics tool sets cookies, yes, you need a banner. The Telecommunicatiewet requires explicit consent for all non-essential cookies, including analytics cookies that don't qualify for the AP's first-party analytics exemption. If your analytics tool is cookieless and meets the audience-measurement exemption criteria under Article 11.7a (no persistent identifiers, no cross-site tracking, first-party only, aggregate output), no Telecommunicatiewet consent is required and no cookie banner is needed for analytics.

The AP runs an automated scanning system that monitors 10,000 Dutch websites annually for cookie compliance. It checks whether cookies fire before consent, whether reject buttons are equally prominent, and whether cookie banners use dark patterns. The Dutch government provides dedicated funding (EUR 500,000/year) for this program. Organizations that fail receive warning letters with a three-month compliance window before formal investigation. Which means you'd get one warning before it gets serious.

The EU Digital Omnibus (proposed November 2025) would create an EU-wide analytics cookie exemption similar to what the Netherlands already has. The Netherlands has raised concerns about the proposal. The EDPB flagged that the exemption is too narrow to cover tools like Google Analytics. Earliest practical impact is 2028. Until then, the Telecommunicatiewet remains the governing law.

A closing note, because this is a legal topic: I'm not a lawyer and this article isn't legal advice. It's a founder's map of the terrain, with every claim linked to the ruling or source it came from. If your setup is complicated, show this to your DPO or lawyer.

And if you're weighing a Dutch analytics decision right now and something here doesn't match what you're seeing, email me.

David Karpik

David Karpik

Founder of Clickport Analytics
Building privacy-focused analytics for website owners who respect their visitors.

Comments

Loading comments...

Leave a comment